OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack | Redhat | 5.0 (including) | 5.0 (including) |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | openstack-glance-0:2014.1.4-1.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | openstack-glance-0:2014.1.4-1.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | openstack-glance-0:2014.2.2-1.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | python-glanceclient-1:0.14.2-2.el7ost | * |
Glance | Ubuntu | trusty | * |